# Hosted API operational handoff

> Coordinate hosted approval, funding, execution, payouts and reconciliation with MyStocks operations.

# How does my trading app connect to MyStocks operations?

Sandbox is an isolated simulation. Hosted Live approval, API credentials, installation licensing and external settlement are separate states. A successful Sandbox journey never approves a production organization or moves real funds.

| Partner action               | Admin task                                                                   | Shared state and evidence                                                        |
| ---------------------------- | ---------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| Submit hosted application    | Review identity and business, approve the organization and production access | Application and organization status, authorized decision, notification and audit |
| Remit firm funding           | Match payment reference, currency and actual receipt before crediting float  | One canonical ledger credit, reference, reviewer and available firm balance      |
| Fund a customer              | Review exceptions and available firm float                                   | Atomic firm-to-customer transfer, customer wallet and ledger entries             |
| Submit a stock order         | Review partner-attributed order in `/admin/dealing-room`                     | Order ID, partner business name, reserved cash/units, executions and remainder   |
| Subscribe to a fund or bond  | Review the corresponding pending investment order and allocation             | Reserved USD, NAV/FX, approved allocation, holding and transaction               |
| Return customer cash to firm | Review account restrictions and settlement holds                             | Customer debit and firm credit; this is not an external payout                   |
| Request an external payout   | Authorize treasury decision and confirm provider outcome                     | Beneficiary, reserved amount, approval, provider reference and ledger            |
| Reconcile a period           | Compare the canonical ledger with independent payment/custody records        | As-of period, discrepancies, evidence and signed review                          |
| Report a delivery problem    | Review webhook attempts and an owned support case                            | Event ID, signature, retries, communication and audit                            |

## What should I show my customer while an order is pending?

Show the actual API order status, reserved balance and filled versus remaining quantity. Request acceptance is not execution. A fill is not independent settlement. Do not enable withdrawals against unsettled proceeds when settlement holds apply. Use event IDs and idempotent handlers; reconnect an event stream with its last event ID.

## How do I safely retry money movement?

Use the same canonical `subAccountId`, endpoint, payload and `Idempotency-Key` for the same logical operation. A changed payload is a new intent and must not be retried under the old key. Inspect wallet, order and ledger state before resolving an uncertain outcome. Use canonical IDs consistently even when an external-ID alias is supported.

## Can a closed account be reopened?

No. A closed account is terminal and cannot be changed back to active through metadata updates. Frozen accounts can be restored through the authorized lifecycle. Money-moving handlers recheck ownership and active state inside their transaction. Create a new account for a new customer relationship; retain the old account's records for review.

## What evidence completes an acceptance test?

Partner action → admin task → authorized decision → shared state → notification → audit evidence → automated test. Email queue insertion proves notification intent, not inbox delivery. Dealing-room tests prove the internal handoff, not execution at an external exchange. A reconciliation response without independent custody/payment data remains incomplete.

Operations can use [admin readiness](/admin/partners?tab=readiness) to find required decisions and their workspaces. Production-only checks need an isolated approved test integration; the public Sandbox reference app does not execute treasury or dealing-room decisions.
